Australian retailers face growing legal risks as AI tools shape customer interactions

Australian retailers are increasingly using artificial intelligence to manage pricing, customer service, and loyalty programs. While these systems can improve efficiency, they also carry legal risks when they provide information that is wrong or misleading. Legal experts warn that businesses remain fully responsible for what AI systems say to customers and the financial consequences can be serious.

David Fischl, legal digital transformation lead partner at Hicksons | Hunt & Hunt, says retailers cannot treat AI as a separate or experimental technology. Under Australian Consumer Law (ACL), businesses are liable if AI-generated product descriptions, prices, or return policies do not reflect reality.

If an AI tool provides incorrect information the retailer will still be held liable under the Australian Consumer Law,” Fischl said.

Penalties for false or misleading representations can reach the greater of $50 million, three times the benefit gained, or 30 per cent of annual turnover. For large retailers, this places AI errors firmly in the category of board-level risk.

AI mistakes can quickly become legal problems

Concerns around AI reliability have grown after several high-profile international incidents. One widely reported case in the United States involved a car dealership chatbot being manipulated by a customer into agreeing to sell a vehicle for US$1 and claiming the deal was legally binding.

While this happened overseas, Fischl says similar risks exist in Australia if guardrails are not in place. Chatbots that can negotiate prices, approve discounts, or make binding statements expose retailers to real legal and reputational harm.

To reduce these risks, he recommends following the Commonwealth Government’s Voluntary AI Standard, which outlines 10 guardrails covering data quality, governance, privacy, cybersecurity, and human oversight.

AI tools should have clear limits,” Fischl said. “The system should not be able to accept offers or make commitments like discounts unless that authority is carefully controlled. Where conversations move into risky areas, the AI should refer customers to a human.”

Governance matters more than the technology itself

As AI becomes embedded in everyday retail operations, Fischl stresses the need for formal governance rather than ad-hoc adoption. This includes assigning executive responsibility for AI use, keeping an inventory of AI systems such as chatbots and recommendation engines, and ranking them by risk.

High-risk, customer-facing tools should undergo careful testing before deployment. This includes checking for accuracy, bias, and compliance with consumer law, with records kept for audits. Ongoing monitoring and clear incident response plans are also essential.

Retailers should also review contracts with AI vendors to ensure technical safeguards, accountability, and clear responsibilities are in place.

Privacy obligations still apply in full

AI systems often rely on large volumes of customer data, which brings privacy obligations into focus. Fischl emphasises that any personal information entered into or generated by AI falls under the Privacy Act 1988 and the Australian Privacy Principles.

Retailers must limit data collection to what is reasonably necessary, clearly inform customers when AI is being used, and explain any secondary purposes such as data analysis or system training. Express consent is required when sensitive information is involved.

Security is another priority. Businesses must take reasonable steps to protect customer data through encryption, access controls, and clear retention and deletion policies.

When working with third-party AI providers, retailers should check where data is stored, who can access it, and whether subcontractors are involved. Contracts should restrict how customer data can be used and include strong breach notification requirements.

Boards urged to prepare for tighter scrutiny

Regulators are paying closer attention to digital practices, and Fischl expects this focus to intensify. Boards are being urged to take an active role in AI oversight, setting clear policies that reflect risk appetite and ensure compliance with consumer and privacy laws.

Boards need to ensure there is clear human oversight over higher-risk decisions that AI tools can make,” Fischl said.

He points to the ACCC’s 2025–26 enforcement priorities, which include misleading pricing and digital platform risks, as well as the Office of the Australian Information Commissioner’s focus on emerging technologies.

By 2026, AI-driven customer interactions are likely to face closer regulatory review. Retailers that embed consumer protection, privacy, and accountability into AI design today will be better placed to manage both legal risk and customer trust in the years ahead.

Exit mobile version